Description: "A flaw was found in rsync in versions since 3.2.0pre1. Rsync improperly validates certificate with host mismatch vulnerability. A remote, unauthenticated attacker could exploit the flaw by performing a man-in-the-middle attack using a valid certificate for another hostname which could compromise confidentiality and integrity of data transmitted using rsync-ssl. The highest threat from this vulnerability is to data confidentiality and integrity. This flaw affects rsync versions before 3.2.4."
Patch: https://git.samba.org/?p=rsync.git;a=commit;h=c3f7414
Package list is empty or all packages have requested keywords.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=029532544d5edfe5fc70413a827831932e3c0b21 commit 029532544d5edfe5fc70413a827831932e3c0b21 Author: Varsha Teratipally <teratipally@google.com> AuthorDate: 2021-11-17 17:30:16 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2021-11-18 02:30:46 +0000 net-misc/rsync: fix CVE-2020-14387 Bug: https://bugs.gentoo.org/792576 Signed-off-by: Varsha Teratipally <teratipally@google.com> Closes: https://github.com/gentoo/gentoo/pull/22981 Signed-off-by: Sam James <sam@gentoo.org> .../files/rsync-3.2.3-verify-certificate.patch | 26 +++++ net-misc/rsync/rsync-3.2.3-r5.ebuild | 124 +++++++++++++++++++++ 2 files changed, 150 insertions(+)
Please cleanup
commit 882b77edf896534ffd91d0fb17696bfda91e635b Author: Sam James <sam@gentoo.org> Date: Sun Apr 17 18:00:47 2022 +0100 net-misc/rsync: drop 3.2.3-r4
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=dff332004f4513f384a402a0411b9418dd99d9c2 commit dff332004f4513f384a402a0411b9418dd99d9c2 Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2024-05-08 06:28:44 +0000 Commit: Hans de Graaff <graaff@gentoo.org> CommitDate: 2024-05-08 06:29:05 +0000 [ GLSA 202405-22 ] rsync: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/792576 Bug: https://bugs.gentoo.org/838724 Bug: https://bugs.gentoo.org/862876 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: Hans de Graaff <graaff@gentoo.org> glsa-202405-22.xml | 46 ++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 46 insertions(+)